CVE-2026-85055
Twenty: Field-level read bypass
Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.22.0, field-level read permission is enforced on selected output fields but not on GraphQL or REST filter predicates. A workspace member or API key with permission to read an object but not a particular field can reference that denied field in direct filters, relation filters, or persisted view filters. The resulting totalCount and row presence reveal whether guesses match the real column, forming a boolean/count oracle that can reconstruct denied field values for records exposed by the principal's row-level policy. This issue is fixed in version 2.22.0.
| CWE | CWE-200 CWE-285 |
| Vendor | twentyhq |
| Product | twenty |
| Published | Sep 22, 2026 |
Get instant alerts for twentyhq twenty
Be the first to know when new unknown vulnerabilities affecting twentyhq twenty are published โ delivered to Slack, Telegram or Discord.